· Ivan Skachkov · GDPR & Compliance · 23 min read

Self-Hosted CISO Assistant: From Fresh Install to a Working ISO 27001, GDPR and NIS2 Portal

Most CISO Assistant guides stop at the login page. This one starts after it is running and takes a self-hosted install to a usable ISO 27001, GDPR and NIS2 portal, in order.

Most CISO Assistant guides stop at the login page. This one starts after it is running and takes a self-hosted install to a usable ISO 27001, GDPR and NIS2 portal, in order.

Most CISO Assistant installation guides stop too early.

They show you how to start the containers, open the login page and create an administrator.

Then you are looking at an empty GRC platform.

Now what?

Where do you create the ISO 27001 scope?

Which modules need to be enabled?

Where do you load ISO 27001?

How do you build the Statement of Applicability?

Where does the old Excel risk register go?

How do you create recurring access reviews?

Where do you put audit evidence?

How do you know whether the portal is actually ready to use?

This guide starts after CISO Assistant is running.

CISO Assistant mascot

It shows the sequence we use to turn a fresh self-hosted CISO Assistant installation into a usable GRC portal.

The examples come from a real Community Edition deployment. Menu names below correspond to CISO Assistant v4.x and can move slightly between releases.

The sequence is:

secure the portalconfigure users and accessload frameworksdefine the ISMSmigrate assets and policiesbuild controlsmigrate risksbuild the ISO 27001 audit and SoAload evidenceadd GDPR and suppliersconfigure findingsestablish the operating cycle

Do it in that order.

Do not start by uploading documents.

1. Log in and secure the administrator account

Open your CISO Assistant URL.

For example:

https://trust.example.com

Sign in with the administrator account created during installation.

CISO Assistant welcome dialog shown after the first login

Do not start creating compliance data yet.

First secure this account.

Open your user menu.

Open your profile.

Change the initial administrator password.

Store the new password in your password manager.

Now open:

Profile → Multi-factor authentication

Enable MFA.

Scan the QR code with your authenticator.

Enter the generated six-digit code.

Save the recovery codes somewhere controlled.

Test that you can log out and log back in.

Check before continuing

You should now have:

a working HTTPS portal;

a working administrator login;

MFA enabled;

the password stored outside the server;

recovery information stored safely.

Do not use this emergency administrator as your normal working account.

Later we will create named administrator accounts.

2. Configure the basic portal settings

Open:

Sidebar → Extra → Settings

Open the General tab.

There are several settings here that are easier to configure now than after you have created hundreds of records.

Email notifications

Find:

Notifications → Enable email notifications

Leave this Off until SMTP has been configured and tested.

We will turn it on later.

Asset security scale

Find:

Assets → Security targets scale

Choose the scale used by your existing risk methodology.

For example, our deployment used:

0–3

because the customer’s existing asset register rated confidentiality, integrity and availability from 0 to 3.

Do this before importing assets.

Changing the scale after the asset inventory has been entered creates unnecessary cleanup work.

Partially compliant results

Find:

Audits → Disable “partially compliant”

Leave this Off.

You want Partially compliant available.

It is useful during migration because many controls are neither completely absent nor fully evidenced.

Self-validation

Find:

Workflows → Allow self-validation

Set this to:

Off

The person creating or changing compliance material should not automatically approve their own work.

MFA enforcement

Find:

Security → Enforce multi-factor authentication

Leave this Off for the moment.

Turn it on after the local users who need MFA have completed their first login.

Personal domains

Find:

Workspace & interface → Personal domains

Leave this:

Off

For a corporate ISMS, objects should live in deliberately designed organisational domains, not personal workspaces.

Save the settings.

3. Enable the modules you are actually going to use

Open:

Extra → Settings → Feature flags

A fresh deployment may have many features disabled.

Do not assume that something does not exist because you cannot see it in the sidebar.

Enable the modules you need.

For an ISO 27001 + GDPR deployment, we normally enable the following.

Organization

Turn on:

Objectives (ISO)Issues (ISO)Journeys

Operations

Turn on:

TasksControl PlanIncidentsFindings managementX-rays

Management and Governance

Turn on:

ReportsThird partyContractsExceptionsPolicy document editorDocument management

Reports is particularly important because it exposes the Statement of Applicability report later.

Compliance

Turn on:

ComplianceFindings from requirementsAdvanced Analytics

Risk management

Turn on:

Risk acceptancesVulnerabilities

GDPR / Privacy

Turn on:

PrivacyPersonal DataPurposesRight RequestsData Breaches

Extra

Turn on:

TerminologiesCommentsRelations graphSSO auto-provisioning / JIT if you intend to use it

Save.

Check

Look at the left sidebar.

You should now see additional areas including things such as:

  • Risk
  • Compliance
  • Operations
  • Privacy
  • Third parties
  • Reports

If Reports is not visible, go back and check the feature flag.

Do not proceed to building the ISO audit until Reports is available.

4. Configure SSO

For a company deployment, do this before creating the normal user population.

The exact identity-provider configuration depends on what you use.

A common setup is Microsoft Entra ID with SAML.

First create the Enterprise Application in Entra.

Then open:

Microsoft Entra admin center → Enterprise applications → your CISO Assistant application → Single sign-on → SAML

Configure the application identifier and reply URL for your portal.

The reply URL follows the CISO Assistant SAML ACS path for your installation.

Copy from Entra:

  • Microsoft Entra Identifier
  • App Federation Metadata URL

Now return to CISO Assistant.

Open:

Extra → Settings → SSO

Open the SAML configuration.

Fill:

IdP Entity ID
Paste the Microsoft Entra Identifier.

Metadata URL
Paste the App Federation Metadata URL.

SP Entity ID
Use the same external identifier configured in Entra.

Review the attribute mappings.

At minimum, verify that email/UID mapping is correct.

Enable:

SSO auto-provisioning / JIT

With JIT enabled, a new person can be created on first SSO login.

That does not mean the new person should automatically receive access to the ISMS.

The account should initially have no useful permissions until you assign the appropriate group.

Save.

Test it before forcing SSO

Open a private/incognito browser.

Sign in using a normal corporate account.

You should arrive in CISO Assistant.

Log out.

Now test the local emergency administrator account again.

Both should work.

Only after both tests succeed should you enable any setting that forces normal users through SSO.

Common problem: “User not declared”

Check that JIT provisioning is enabled.

Common problem: only some people cannot log in

Check email address casing and mapping between the identity provider and CISO Assistant.

Common problem: login redirects to HTTP or an internal backend hostname

That is normally an external URL / reverse-proxy header problem.

Fix the deployment configuration before continuing.

Common problem: error 500 after SAML login

Recheck:

  • Entity ID;
  • metadata URL;
  • Reply URL;
  • attribute mappings.

Do not continue until SSO works reliably.

5. Configure email and test it

CISO Assistant needs email for more than marketing-style notifications.

It is used for operational things such as:

  • password reset;
  • evidence expiry;
  • task notifications;
  • due dates;
  • findings.

SMTP is configured at deployment level rather than entirely through the web interface.

Use a dedicated service mailbox.

Do not use an employee’s personal mailbox.

After SMTP has been configured on the host, return to:

Extra → Settings → General

Enable:

Notifications → Enable email notifications

Now test it.

Use the password-reset function on a test account.

The test is not:

“The SMTP variables exist.”

The test is:

“An actual message arrived.”

If mail does not arrive, fix it now.

Do not create external local users until password reset and notification email work.

6. Take the first backup

Before building the ISMS, take a known-good backup.

Open:

Extra → Backup & restore

Create a backup.

Keep host-level database backups as well.

The application backup is not a reason to stop backing up PostgreSQL and the evidence volume.

Rule for the rest of the implementation

Take another backup:

  • before large imports;
  • before risk migration;
  • before mass API changes;
  • after completing each major phase.

Do not learn whether your backup works on the day you need it.

7. Create the organisational domains

Now we create the access structure.

Open:

Organization → Domains

Click the purple + button.

Create the main ISMS domain first.

Example:

Name

Company - ISMS

Description

Corporate ISMS: audits, policies, corporate risks, suppliers, findings and management review

Create IAM groups
On

Click Save.

Now create other domains only where a real access or ownership boundary exists.

For example:

  • Company - Technology
  • Company - Operations
  • Company - Finance

Do not reproduce your entire organisation chart simply because you can.

Domains are primarily access boundaries.

Check

Open:

Organization → Domains

You should see your new domains.

Now open:

Organization → User groups

For each domain, CISO Assistant should have created role groups such as:

  • Analyst
  • Approver
  • Domain manager
  • Reader
  • Respondent
  • Technical tester

If those groups were not created, go back and check whether Create IAM groups was enabled when the domain was created.

8. Create the ISMS perimeter

A domain is not the ISO 27001 scope.

Create the scope separately as a perimeter.

Open:

Organization → Perimeters

Click +.

Create the main ISO 27001 perimeter.

Example:

Name

ISMS-27001

Description
Paste the actual approved ISO 27001 scope statement.

Do not write:

Company information systems

unless that is genuinely your approved scope.

Use the wording from your ISMS documentation or certificate.

Domain

Company - ISMS

Reference ID

PER-ISMS-001

Status

Production

Use Production if this is an already operating ISMS.

Use Design only if the scope genuinely has not gone live yet.

Save.

If you need them, create additional perimeters such as:

  • GDPR-Processing
  • TECH-Platform
  • OPS-Production
  • FIN-Systems

Important

Perimeters are not the same as access boundaries.

If access must be separated, use domains.

9. Remove the demonstration data

Do this before you start putting real company data into the portal.

A fresh installation may contain demonstration objects.

Open:

Organization → Perimeters

Look for demonstration data such as:

EU SaaS Startup

Open it.

Check which objects are linked to it.

Remove the linked demo:

  • audits;
  • risk assessments;
  • assets;
  • other sample records.

Then delete the demonstration perimeter.

Check

Search the portal for the sample company name.

Nothing belonging to the sample organisation should remain.

You do not want a fictional SaaS startup appearing in an export given to your ISO auditor.

10. Create your named administrator

Stop using the break-glass account for normal work.

Open:

Organization → Users → Add user

Enter your normal corporate email address.

Use exactly the same email identity used by your SSO provider.

Save.

Open the user.

Open:

User groups

Add:

Global - Administrator

Log out.

Log back in using your named account.

Confirm that you can administer the portal.

From this point, keep the original administrator only for emergencies.

11. Let normal users arrive through SSO

If JIT provisioning is enabled, do not manually create everybody.

Ask the first ISMS user to sign in using SSO.

Now open:

Organization → Users

The new account should exist.

Open it.

Open:

User groups

Assign the required role.

For example:

ISMS manager:

ISMS Domain manager

Security manager:

Technology Domain manager

ISMS Analyst

IT:

Technology Analyst

DPO:

ISMS Analyst

Management:

ISMS Approver

Internal auditor:

Reader

External auditor:

Reader with an expiry date

Check permissions

Use a non-administrator test account.

Confirm that the account can see what it is supposed to see.

Confirm that it cannot edit objects outside its role.

Do this now.

Do not discover your access model is wrong during the certification audit.

12. Check the framework libraries

Open:

Governance → Libraries

Open:

Loaded libraries

Search for:

27001

Confirm that:

International standard ISO/IEC 27001:2022

is loaded.

Search:

GDPR

Confirm that GDPR is loaded if you need the privacy assessment.

Search:

NIS2

Check which NIS2 framework/mapping libraries are present for your version.

Do not unload libraries simply because you are not using them.

Unused mapping libraries do nothing until you actually apply them.

Check the risk matrix

Open:

Catalog → Risk matrices

Look at the available matrices.

If your company uses the standard matrix supplied by CISO Assistant, fine.

If it uses its own approved matrix, stop here and import that matrix before creating risk assessments.

Once a risk assessment is created with a matrix, changing it later is not a trivial correction.

13. Import a custom risk matrix if required

If your existing risk methodology uses its own matrix, prepare it as a CISO Assistant library.

Then open:

Governance → Libraries → Libraries store

Click the Import / Upload button.

Select the library file.

Confirm the import.

Now open:

Loaded libraries

Find your matrix library.

Then open:

Catalog → Risk matrices

Confirm that the matrix appears.

Open it.

Check the orientation visually.

For a 4×4 matrix, check at least:

  • low probability + low impact;
  • high probability + high impact;
  • the treatment-threshold cells.

Do not assume the rows and columns were interpreted correctly.

Check

Now open:

Risk → Risk assessments → +

Your custom matrix should be available in the Risk matrix selector.

Do not create the risk assessment yet.

Close the form.

The point was only to verify that the matrix is available.

14. Start the ISO 27001 journey

If your version contains the ISO 27001 journey, use it.

Open:

Overview → Journeys

Click:

Start a journey

Choose:

ISO 27001:2022 — Full Implementation

Select:

Use an existing domain

Choose your ISMS domain.

Enable:

Create underlying objects

This is important.

If you leave this unchecked, the journey is mainly a checklist.

If you enable it, CISO Assistant creates useful underlying objects.

Leave:

Adjust menu and modules

unchecked if you have already configured your feature flags manually.

Start the journey.

Now inspect what it created

Go through the objects created by the journey.

It may create:

  • ISO issues;
  • objectives;
  • an ISO 27001 audit;
  • task templates;
  • metrics;
  • applied controls;
  • a risk assessment;
  • a findings binder.

Do not accept everything blindly.

If it created a risk assessment using the standard 5×5 matrix but your organisation uses a custom 4×4 matrix:

Risk → Risk assessments

Open the generated assessment.

Delete it if it contains no real data.

You will create the correct assessment later.

Check

Open:

Compliance → Audits

You should see the ISO 27001 compliance assessment created by the journey.

Keep it.

We will configure it later.

15. Create the ISO context issues

Open:

Governance → Issues (ISO)

Click +.

Create one record for each material internal or external issue.

Example:

Name

Dependence on external contractors

Category
Choose the appropriate category.

Origin

Internal

Status

Active

Description
Explain why this affects the ISMS.

Save.

Create the next issue.

Examples include:

  • cyberattack environment;
  • cloud dependency;
  • staff turnover;
  • legal obligations;
  • market requirements;
  • AI adoption;
  • reliance on key suppliers;
  • climate-change relevance.

Do not write a textbook SWOT analysis here.

Use the organisation’s actual context assessment.

16. Create interested parties

For each significant interested party, create an Entity.

Open:

Third parties → Entities

Click +.

Examples:

  • management;
  • employees;
  • customers;
  • suppliers;
  • contractors;
  • regulators;
  • ICT suppliers.

For each entity, put into the description:

  • needs;
  • expectations;
  • requirements;
  • how the ISMS addresses them.

Save.

This gives clause 4.2 somewhere structured to live instead of leaving the entire analysis inside one Word file.

17. Create ISO security objectives

Open:

Governance → Objectives (ISO)

Click +.

Do not invent generic objectives just to fill the screen.

Take the objectives management has actually approved.

Examples:

  • complete two phishing simulations;
  • achieve a defined MFA coverage;
  • perform an annual disaster-recovery test;
  • close a specific audit finding;
  • reduce high-risk vulnerabilities within the defined SLA.

Enter:

  • objective;
  • owner;
  • target;
  • dates;
  • status.

Save each one.

18. Import the asset inventory

Take a backup first.

Now open:

Assets management → Assets

Click +.

Start with the important services.

Do not start with every laptop.

Example:

Name

Microsoft 365

Description
Explain what the organisation uses it for.

Business value
Explain why the service matters.

Owner
Select the accountable person.

Domain
Choose the correct organisational domain.

Type
Choose Primary or Supporting.

Use Primary for important business services/information.

Use Supporting for systems, software, infrastructure, people or facilities that support those services.

Set the security objectives.

For example:

Confidentiality
2

Integrity
3

Availability
3

If you maintain recovery targets, enter:

  • RTO;
  • RPO;
  • MTD.

Add useful labels such as:

  • type:saas
  • criticality:critical
  • classification:confidential
  • subprocessor:yes

Save.

Load order

Do this in this order:

  1. business services;
  2. important information assets;
  3. supporting systems;
  4. infrastructure;
  5. important SaaS platforms;
  6. hardware where it matters to the risk model.

This allows you to link supporting assets to their parent services.

Check

Open the Assets list.

Verify that each important asset has:

  • an owner;
  • a domain;
  • C/I/A values;
  • classification;
  • recovery data where required.

If an availability-critical service has no recovery target, fix that before continuing.

19. Create policies as managed objects

Open:

Governance → Policies

Click +.

Do not simply upload every Word document.

Create a proper policy record.

Example:

Name

Information Security Policy v2026-01

Reference ID

POL-ISP-01

Owner
ISMS Manager

Status

Active

Use Active only if an approved document really exists.

Set:

Start date

Set:

Expiry date

Use the expiry date as the next mandatory review date.

Attach the approved document.

If the authoritative copy stays in SharePoint, put the SharePoint address into:

Link

Save.

Repeat for the main policies:

  • Information Security
  • Acceptable Use
  • Access Control
  • Password / Authentication
  • Cryptography
  • Classification
  • Retention
  • Backup
  • Disaster Recovery
  • Asset Management
  • Physical Security
  • Risk Management
  • Vulnerability Management
  • Incident Management
  • Security Awareness
  • Data Protection
  • Supplier Security
  • Change Management

Add others that actually exist in your organisation.

Check

Open:

Overview → Analytics → Governance

Look at the policy/watch-list information.

A policy approaching its expiry date should be visible as something requiring attention.

That is the behaviour you want.

20. Configure applied controls

Open:

Operations → Applied controls

If you started the ISO journey, you may already have many controls in status To do.

Do not create another copy.

Open an existing control.

Set:

Owner

Set:

Status

Use:

  • To do
  • In progress
  • On hold
  • Active
  • Degraded
  • Deprecated

Only use Active when the control really operates.

Example:

Open the control corresponding to access management.

Set the owner to the security manager.

Add a description of what the organisation actually does.

For example:

Corporate identities are managed through Entra ID. MFA is required. Privileged access requires approval. Leaver accounts are disabled as part of the HR offboarding process. Access is reviewed quarterly.

Link relevant assets.

Set dates if appropriate.

Save.

Repeat for the real controls.

Important rule

Do not describe the ISO requirement again.

Describe your implementation.

21. Create the recurring control tasks

Open:

Operations → Tasks

Create a task template.

Start with access review.

Click +.

Name

Quarterly user access review

Recurrent
Yes

Frequency
Every 3 months

Assigned to
Security Manager

In the description, write the actual procedure.

For example:

  1. export active users from the identity provider;
  2. export privileged-role assignments;
  3. compare with active employees;
  4. identify inactive or unjustified access;
  5. ask the responsible manager to confirm retain/remove/change;
  6. implement changes;
  7. attach the completed review.

Link the task to the access-control applied control.

Save.

Now create the rest of the real operating calendar.

At minimum consider:

Weekly

vulnerability triage.

Monthly

asset inventory check;

patch review;

device posture;

KPI collection;

threat-intelligence review.

Quarterly

access review;

operational control review;

backup restore test;

incident report.

Yearly

risk review;

internal audit;

management review;

policy review;

supplier assessment;

penetration test;

security awareness;

DR exercise.

CISO Assistant Tasks list with recurring tasks, frequencies and next occurrence dates

Now open:

Operations → Control Plan

You should see upcoming and overdue work.

Open:

Operations → Calendar

Verify the dates.

That is the moment the ISMS begins to behave like an operating system instead of a document archive.

22. Create the real risk assessment

Now that the assets, controls and matrix exist, create the risk assessment.

Open:

Risk → Risk assessments

Click +.

Example:

Name

2026 Technology Risk Assessment

Reference ID

RA-2026-TECH

Perimeter

TECH-Platform

Version

2026.1

Status

In progress

Risk matrix
Select the matrix approved for your organisation.

Be careful here.

The matrix is an important structural choice.

Check it before saving.

Set:

Authors

Set:

Reviewers

Set:

Due date

Set:

Risk tolerance

according to the approved methodology.

Save.

23. Enter a risk scenario — click by click

Open:

Risk → Risk scenarios

Click +.

Example:

Name

Loss of power to critical infrastructure

Risk assessment
Select the assessment you just created.

Reference

RS-TECH-001

Threat
Select the appropriate threat.

Click Save.

Now open the scenario.

Click Edit.

Set:

Owner

Select the relevant asset.

Select or create the vulnerability.

Example:

UPS cannot sustain the required load during power failure

Now go to the Current risk section.

Choose the relevant existing controls.

Set:

Current probability

Set:

Current impact

CISO Assistant should calculate the risk level from the matrix.

Now go to Residual risk.

If treatment is required, add an extra control.

Example:

Replace and test UPS

Set:

  • owner;
  • priority;
  • ETA;
  • cost if used;
  • status.

Now set the expected residual probability and residual impact.

Set:

Treatment status

For example:

Mitigated

Add the justification.

Save.

Check

The treatment control should also appear in:

Operations → Applied controls

The scenario should show both current and residual risk.

If either is missing, do not move to the next scenario.

24. Create formal risk acceptance

Where residual risk is being accepted, do not leave the decision buried in a meeting minute.

Open:

Governance → Risk acceptances

Click +.

Enter:

Name

Residual risk acceptance – 2026 Technology

Approver
The management user authorised to accept the risk.

Risk scenarios
Select the scenarios being accepted.

Justification
Reference the treatment decision.

Expiry date
Set the next review date.

Save.

The normal flow is:

Created → Submitted → Accepted

The analyst submits.

The approver decides.

Now open:

Operations → X-rays

Check for problems such as:

  • scenario says Accepted but has no acceptance;
  • acceptance has expired;
  • other inconsistent risk states.

Fix the X-rays before continuing.

25. Configure the ISO 27001 audit

Open:

Compliance → Audits

If the ISO journey created an audit, open that one.

Do not create a duplicate.

Otherwise click +.

Enter:

Name

ISO 27001:2022 – ISMS 2026

Reference ID

AUD-27001-2026

Perimeter

ISMS-27001

Target framework

International standard ISO/IEC 27001:2022

Selected implementation groups

Choose both:

  • Clauses
  • Statement of Applicability (SoA)

Version

2026.1

Status

In progress

Authors
ISMS team

Reviewers
Management / internal auditor

If you have not already generated framework controls, enable:

Suggest controls

Save.

Check

The audit page should contain:

framework;

perimeter;

authors;

reviewers;

maturity/compliance information;

progress;

associated requirements.

You should see requirements covering clauses 4–10 and the Annex A controls.

26. Assess one ISO control properly

Do one control completely before trying to fill 93 rows.

In:

Compliance → Audits → your ISO audit

scroll to:

Associated requirements

Open:

5.15 Access control

A panel opens.

Open the:

Applied controls

tab.

Attach your existing access-control implementation.

Do not create another duplicate control unless one genuinely does not exist.

Open:

Evidences

Link evidence if appropriate.

Now set:

Status

This is the workflow state:

To do

In progress

In review

Done

Now set:

Result

This is the compliance conclusion:

Compliant

Partially compliant

Non compliant

Not applicable

Not assessed

Do not confuse these fields.

A requirement can be:

Status: Done

and:

Result: Non compliant

because the assessment work has been completed and the conclusion is that the company does not comply.

Now fill:

Observation

Write the actual justification.

This text later feeds the Statement of Applicability.

Save.

Your rule for Compliant

Use Compliant only when:

the control exists;

it is Active;

the evidence is current;

the implementation actually satisfies the requirement.

If something is still being remediated, use Partially compliant or Non compliant as appropriate.

Do not mark it compliant because “we have a policy about it.”

27. Build the Statement of Applicability

Work through Annex A.

For each control:

  1. open the requirement;
  2. decide applicability;
  3. attach the relevant applied control;
  4. attach current evidence;
  5. write the justification;
  6. set Result;
  7. set workflow Status;
  8. save.

For a non-applicable control, choose:

Result → Not applicable

Then write why in Observation.

For example, if outsourced software development genuinely does not occur:

The organisation does not outsource software development. Software development activities are performed internally.

Do not enter:

N/A

That is not a justification.

28. Export the real SoA

Once the assessment is populated, open:

Overview → Reports

Choose:

Statement of Applicability

Select your audit.

Optionally select the relevant risk assessments.

Select the SoA implementation group.

Click:

Render

Review the columns.

You should see information such as:

  • reference;
  • applicable;
  • justification;
  • implementation;
  • reference control;
  • additional controls;
  • risk coverage.

Now export the report to PDF.

Open the PDF.

Read several rows.

Make sure the Observation text you entered actually produces a useful SoA.

If the PDF is full of empty or useless justifications, go back to the audit and correct the records.

Do not manually edit the exported PDF to hide weak data.

Fix the source.

29. Add evidence from the control

The easiest way to manage evidence is from the control it supports.

Open:

Operations → Applied controls

Open a control.

Open the:

Evidences

tab.

Click:

+ Add evidence

Example:

Name

EV-ACC-01-access-review

Description

Quarterly review of Entra ID users and privileged roles

Upload the attachment or add the controlled source link.

Set:

Owner

Set:

Status

For approved evidence:

Approved

Set:

Expiry date

For a quarterly access review, use roughly three months.

Save.

Renew evidence correctly

Three months later, do not create:

EV-ACC-02

Open the existing evidence record.

Add a new revision.

Attach the new quarter’s file.

Record the version/date.

Keep one stable evidence object and renew it with revisions.

That gives you history without filling the system with duplicate records.

30. Test evidence expiry

Create a temporary evidence item with a near expiry date.

Verify that it appears in the appropriate watch/expiry views.

The operating model should be:

current evidence → valid control proof.

expired evidence → requires review.

The system should make stale evidence visible.

Do not rely on somebody remembering the date from the filename.

31. Build the GDPR register

Enable the Privacy features first if you have not already done so.

Now use this order.

Purposes

Open:

Privacy → Purposes

Click +.

Create purposes such as:

  • customer service delivery;
  • employee administration;
  • invoicing;
  • marketing;
  • supplier management.

Save.

Personal data

Open:

Privacy → Personal data

Click +.

Create categories.

Examples:

  • employee identification data;
  • customer contact data;
  • billing information;
  • authentication logs.

Set retention and sensitivity where available.

Save.

Processing activities

Open:

Privacy → Processings

Click +.

For each processing activity fill:

  • name;
  • description;
  • legal basis;
  • data subjects;
  • personal-data categories;
  • purposes;
  • recipients;
  • international transfers;
  • retention;
  • owner;
  • security measures.

For security measures, link the applied controls that already exist.

Do not rebuild separate GDPR access-control and encryption controls if the ISO controls already perform the job.

Save.

32. Test a data-subject request

Open:

Privacy → Right requests

Click +.

Create a test request.

Set the request type.

For example:

Access

Enter only the personal information required to manage the request.

Set:

Received date

Set:

Due date

according to the legal/procedural requirement.

Assign the owner.

Link the relevant processing activity.

Save.

Now make sure the due date is visible to the responsible user.

Once confirmed, remove the test record if it is not a real case.

33. Configure the breach register

Open:

Privacy → Data breaches

Click +.

Review the fields before the organisation has a real breach.

You should know where to record:

  • detection time;
  • description;
  • affected data;
  • affected people;
  • consequences;
  • containment;
  • notification decision;
  • authority notification;
  • communication to affected people.

Do not discover the data-breach form for the first time during an incident.

34. Create the GDPR audit

Open:

Compliance → Audits

Click +.

Select:

Framework → GDPR

Select:

Perimeter → GDPR-Processing

Set the DPO/privacy lead as author.

Set the appropriate management reviewer.

Save.

Now assess the requirements exactly as you did for ISO 27001.

Reuse the controls you already built.

That is one of the main reasons for using a GRC platform instead of separate GDPR and ISO spreadsheets.

35. Build the supplier register

Open:

Third parties → Entities

Click +.

Start with important suppliers.

Enter:

Name

Description

Domain

Mission

Owner

Set the available criticality/risk inputs.

Save.

Now open:

Third parties → Solutions

Create the service you buy from that entity.

For example:

Entity:

Microsoft

Solution:

Microsoft 365

Another example:

Entity:

AWS

Solution:

S3 backup storage

Now open:

Third parties → Contracts

Create the associated contract.

Set:

  • start date;
  • renewal/expiry where applicable;
  • owner.

Attach or link the contract/DPA as evidence.

36. Create a supplier assessment

Open:

Third parties → Entity assessments

Click +.

Example:

Name

AWS 2026 Security Review

Perimeter

ISMS-27001

Entity

AWS

Framework / questionnaire
Choose the vendor questionnaire you use.

Authors

Reviewers

Representative
If the supplier will answer directly.

Expiry date
For critical/high suppliers, normally set the next required review date.

Complete the assessment.

Set the conclusion.

Save.

Check

The supplier record should now tell you:

what you buy;

who owns the relationship;

what contract exists;

what assessment was performed;

what evidence was reviewed;

when reassessment is due.

If the answer to any of those is “look in the supplier folder,” migration is not finished.

37. Configure incidents

Open:

Operations → Incidents

Click +.

Review the fields.

Your incident record should capture at least:

  • name;
  • description;
  • severity;
  • status;
  • detection source;
  • owner;
  • affected assets;
  • evidence;
  • timeline.

If your operational ticket remains in Freshservice, Jira, osTicket or another tool, keep it there.

Use CISO Assistant to hold the GRC record and link to the operational ticket.

Do not force your technical incident team to abandon a working incident-response tool merely because the GRC platform has an Incident object.

38. Create findings binders

Open:

Governance → Findings binders

Create one binder for each major source.

Examples:

  • External certification audit 2026
  • Internal audit 2026
  • Penetration test 2026
  • Vulnerabilities
  • Continuous control monitoring

Now create the findings.

For each finding record:

  • original finding;
  • reference;
  • related requirement;
  • owner;
  • priority;
  • target date;
  • root cause;
  • corrective control.

Do not mark the finding Closed merely because somebody says it has been fixed.

Attach effectiveness evidence first.

Then close it.

39. Configure security exceptions

Open:

Governance → Exceptions

Click +.

Example:

Name

Legacy system cannot enforce current password policy

Description
Explain the actual exception.

Owner

Approver

Severity

Status

Expiration date

Never create permanent exceptions.

Link:

  • affected control;
  • affected asset;
  • risk scenario;
  • compensating evidence.

Save.

The corresponding risk should also exist in the risk register.

An exception is not a magic button that makes a risk disappear.

40. Run the internal audit from the portal

Before the internal audit, create a Reader account for the auditor or provide controlled exports.

The auditor should work from the current ISO audit.

Open:

Compliance → Audits → AUD-27001-2026

Review each sampled requirement.

Reviewer comments go into Observation or into a Finding where a discrepancy exists.

Attach the internal audit report as evidence against clause 9.2.

When the audit has been formally signed off:

set the audit:

Status → Done

then enable:

Locked

Now the year’s assessment is frozen.

Do not keep editing the signed-off audit.

For the next cycle, create a new audit using the previous one as the baseline.

41. Prepare the management review from live data

Before the management review, open:

Operations → X-rays

Resolve data-quality issues.

Open:

Operations → Control Plan

Look for overdue activities.

Open:

Overview → Analytics

Review Governance, Risk and Compliance.

Export:

  • open actions;
  • audit status;
  • findings;
  • SoA;
  • supplier assessments;
  • risk assessment;
  • objectives;
  • metrics.

The management review should consume this live information.

After the meeting, every management decision that requires work should become either:

  • an applied control;
  • a task;
  • a risk decision;
  • a finding/action.

Give it:

  • an owner;
  • an ETA.

Attach the approved meeting minutes as evidence against ISO 27001 clause 9.3.

42. Configure the system for day-to-day operation

At this point the installation is no longer the project.

Running it is.

CISO Assistant Assignments page with upcoming tasks, audits, exceptions and findings binders

Open:

Operations → Control Plan

This should become a normal working screen.

Someone must review it.

Open:

Overview → Analytics

Someone must review expiring material.

Open:

Operations → X-rays

Someone must resolve inconsistencies.

Review:

Risk acceptances

Someone must renew or revoke expiring acceptances.

Review:

Third parties → Entity assessments

Someone must reassess suppliers.

Review:

Governance → Policies

Someone must update expiring policies.

If nobody owns those activities, the portal will slowly turn back into the same stale compliance system you were trying to replace.

43. Four weeks before the certification or surveillance audit

Run this checklist in the portal.

Policies

Open the Governance watch list.

There should be no unexplained expired policy.

Evidence

Filter evidence for expired or missing records.

Renew what is legitimately due.

Do not backdate evidence.

Applied controls

Open:

Operations → Applied controls

Filter for:

Degraded

Investigate every one.

Tasks

Open:

Operations → Control Plan

There should be no unexplained overdue recurring obligation.

Risks

Open each risk assessment.

Check that it has been reviewed within the required cycle.

Check High/Very High residual risks.

Open:

Governance → Risk acceptances

Make sure required acceptances exist and have not expired.

Run:

Operations → X-rays

Resolve inconsistencies.

Findings

Open the last certification/internal audit binder.

Every finding claimed as closed should have effectiveness evidence.

Statement of Applicability

Open:

Overview → Reports → Statement of Applicability

Render it again.

Read the N/A rows.

Every N/A needs an actual justification.

Read several Compliant rows.

Make sure they point to real controls and evidence.

Internal audit and management review

Make sure both have occurred within the required cycle and that their evidence is attached.

Suppliers

Check that required annual supplier reviews are complete.

Owners

Check that controls, risks, policies and evidence do not belong to somebody who left six months ago.

44. Give the external auditor access

If the auditor needs portal access:

Open:

Organization → Users → Add user

Create the auditor account.

Set an:

Expiry date

Add:

Reader

on the required domains.

Do not give Analyst or Administrator because it is easier.

Test the auditor account yourself before the audit begins.

If force-SSO is enabled and the auditor is external, either:

  • invite the auditor through your identity provider as a guest;
  • or use controlled exports.

Do not disable SSO for the entire company simply to accommodate one external auditor.

After the audit, remove their access.

Keep the removal record as access-review evidence.

45. What “finished” looks like

You do not have a finished CISO Assistant deployment because the home page opens.

You have a finished first implementation when somebody can open the portal and answer:

What is our ISO 27001 scope?

Open the perimeter.

Which policies need review?

Open Policies / Watch list.

Which controls are not working?

Open Applied controls and filter Degraded.

Which compliance work is overdue?

Open Control Plan.

Which risks remain high?

Open Risk assessments.

Who accepted them?

Open Risk acceptances.

Why is Annex A control 8.30 not applicable?

Open the ISO audit requirement.

Show me the Statement of Applicability.

Open Reports → Statement of Applicability.

Show me the latest access review.

Open the access-control evidence.

When does it expire?

Read the evidence record.

Which suppliers need to be reviewed this year?

Open Entity assessments.

What findings remain open from the previous audit?

Open the findings binder.

What will happen next month even if the ISMS manager forgets?

Open Tasks and Control Plan.

That is the point.

The goal of self-hosting CISO Assistant is not to have another application running on a server.

The goal is to get the compliance process out of people’s heads, spreadsheets and folder structures and put it into a system that tells you what exists, who owns it, whether it is current and what has to happen next.

Where Futurion Solutions comes in

This is also why our CISO Assistant work is not sold as a Docker installation.

We deploy the platform, but the deployment is only the beginning.

The actual engagement covers:

Assessmentproduction deploymentISMS migrationcontrol and evidence automationoperating handover

That includes taking the existing Excel/Word/SharePoint system and turning it into the objects described in this guide: domains, perimeters, assets, policies, controls, risks, audits, evidence, supplier assessments, findings and recurring work.

Where useful, we then connect the portal to the systems that already contain compliance evidence so recurring checks do not depend on somebody exporting the same report every month.

CISO Assistant Workflows list with scheduled evidence-collection workflows

The finished result should be something the client’s own team can operate after handover.

Back to Blog

Related Posts

View all posts »